How to block Vlans from seeing each other on the netowk

How to block Vlans from seeing each other on the netowk

How to block Vlans from seeing each other on the netowk
How to block Vlans from seeing each other on the netowk
2025-03-10 00:09:49 - last edited 2025-03-10 02:23:31
Model: TL-SG108PE  
Hardware Version: V2
Firmware Version: 1.0.1 Build 20211021 Rel.56865

I have the ER605 Router with no controller. I have successfully setup my Vlans and all traffic is being routed correctly. However How do I ban say Vlan from seeing Vlan 2 etc. I am not sure where this is done. Is it in the router or each switch ? 

 

All of my Vlans have the same subnet so I Am not sure if I have to change the subnet for each vlan. 

 

 

Is this done under Access Control in the firewall ? 

 

 

Also if my main computer is on Vlan 1 and I am running Plex, DNLA Server. If I drop my TVS on Vlan 2 and block Vlan traffic from each other, How do I give Vlan 2 access to say PLESK on Vlan 1 ? A Single application. 

  0      
  0      
#1
Options
1 Accepted Solution
Re:How to block Vlans from seeing each other on the netowk-Solution
2025-03-10 02:22:32 - last edited 2025-03-10 02:23:31

Hi @johngalt 

Thanks for posting in our business forum.

Same VLAN ID means the same subnet.

Devices in the same subnet will receive the ARP.

Then they discover each other.

 

Set them in different subnets = VLAN, you will not receive the ARP from them and not see them.

The price for not seeing them, if you insist, is to block the ARP, and you will lose connection for LAN and Internet.

There is no workaround for this. Just separate them in different VLAN interfaces.

 

If you use ACL to block VLAN 1 and 2 from accessing each other, there is no way to bypass it due to the rule you've set.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#3
Options
4 Reply
Re:How to block Vlans from seeing each other on the netowk-Solution
2025-03-10 02:22:32 - last edited 2025-03-10 02:23:31

Hi @johngalt 

Thanks for posting in our business forum.

Same VLAN ID means the same subnet.

Devices in the same subnet will receive the ARP.

Then they discover each other.

 

Set them in different subnets = VLAN, you will not receive the ARP from them and not see them.

The price for not seeing them, if you insist, is to block the ARP, and you will lose connection for LAN and Internet.

There is no workaround for this. Just separate them in different VLAN interfaces.

 

If you use ACL to block VLAN 1 and 2 from accessing each other, there is no way to bypass it due to the rule you've set.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#3
Options
Re:How to block Vlans from seeing each other on the netowk
2025-03-10 04:21:38
Not sure I follow: So should I add each VLAN in its own subnet ?
  0  
  0  
#4
Options
Re:How to block Vlans from seeing each other on the netowk
2025-03-10 07:20:22

Hi @johngalt 

Thanks for posting in our business forum.

johngalt wrote

Not sure I follow: So should I add each VLAN in its own subnet ?

Something like this:

How to Set Up VLAN Interface on the Omada Router

 

Each subnet means a broadcast area. You want them not to see each other in different VLANs, so separate them.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#5
Options
Re:How to block Vlans from seeing each other on the netowk
2025-03-11 02:23:43

  @johngalt  i am not using the omada controller and my switches are switches that can't be controlled in omada.

 

  0  
  0  
#6
Options